SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Filling Risk Treatment Table

  Quote
Guest
Guest user Created:   Dec 06, 2017 Last commented:   Dec 06, 2017

Filling Risk Treatment Table

Could you also provide guidance for what should be inserted in Acceptance of Residual Risks columns? Especially Vulnerability, New impact, new probability and Residual risk columns.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 06, 2017

No. Name of asset Asset owner Threat Vulnerability New impact New probability Residual risk

Answer: In columns A to I from the Risk Treatment Table you have to fill in the values you have identified in the Risk Assessment process considering the risks identified as unacceptable. Then after the identification of proper risk treatment options and means of implementation you have to identify the new values for impact, probability and residual risks, considering the effects of the proposed control will have on them.

These articles will provide you further explanation about Risk assessment and treatment process:
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- Why is residual risk so important? https://adviser a.com/27001academy/knowledgebase/why-is-residual-risk-so-important/
- How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
- 4 mitigation options in risk treatment according to ISO 27001 https://advisera.com/27001academy/blog/2016/05/16/4-mitigation-options-risk-treatment-according-iso-27001/

These materials will also help you regarding Risk assessment and treatment process:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 06, 2017

Dec 06, 2017

Suggested Topics

Guest user Created:   Dec 19, 2019 ISO 27001 & 22301
Replies: 1
0 0

Context document

Guest user Created:   Mar 31, 2019 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content